PPosseon Finance

Data Retention and Deletion

Effective September 25, 2026

Our approach

Posseon Finance keeps only the information needed for bookkeeping, cash planning, security, recovery, and legally required recordkeeping.

Bank connections

Plaid access tokens are kept only while a connection is active. Disconnecting must revoke the Plaid Item, delete the local token and cached account snapshots, and stop future synchronization.

Financial records and receipts

Transactions, classifications, receipts, and expense proof are retained while needed for the owner's accounting, tax, audit, or legal obligations. They are deleted securely after those obligations end or at the owner's direction when no obligation applies.

Backups and security records

Expired encrypted backups are securely removed through routine rotation. Security and audit records are kept only while needed to investigate events and document owner-approved actions.

Requests

The owner may request access, correction, export, or deletion. Posseon records the request, verifies authority, and documents any information that must be retained and why.

Review

This policy is reviewed every January and whenever Posseon Finance changes its bank provider, hosting, storage, user model, or legal obligations. The next scheduled review is January 2027.

Contact

Data requests: hello@posseon.com